A credential phishing campaign used fake "New Audio MSG" emails to lure recipients to a Play Audio link that passed through multiple tracking and redirect stages before landing on a Google-themed sign-in page. Researchers said the operation carried a Base64-encoded copy of the target’s email address through the chain to personalize the final page, which impersonated Google Accounts, Google Workspace, or Google Voice. The phishing flow abused trusted-looking infrastructure and cloud services, including Framer-hosted pages and Cloudflare Workers, to make the delivery path appear legitimate and harder to block.
The final phishing stages used HTML smuggling techniques aligned with MITRE ATT&CK T1027.006, including JavaScript Blob objects and inline content reconstruction, to hide or dynamically generate malicious content in the victim’s browser. LevelBlue also observed related multi-stage campaigns using custom CAPTCHA, anti-debugging logic, Web Crypto API decryption, and newly registered domains, with one chain ending in OneDrive device-code phishing. Researchers warned that layered redirects and inline browser-side payload generation can evade static blocklists and recommended preserving full redirect chains, correlating email clicks with login attempts, and blocking malicious destinations across email, web, and DNS controls.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Splunk Threat Research removed the hunting analytic "Splunk HTTP Response Splitting Via Rest SPL Command" from its content library in version 5.6.0, stating the associated CVEs had been patched in the latest Splunk release. The removed analytic had been intended to detect attempts to exploit an HTTP response splitting vulnerability via REST SPL commands.
LevelBlue also identified a second phishing campaign that used newly registered domains in a staged redirect chain ending in a OneDrive-themed device code phishing page. The final page included anti-debugging measures, and LevelBlue said all URLs in the chain were less than one year old and were classified as phishing only by LevelBlue at the time of analysis.
LevelBlue identified a phishing campaign that used Framer-hosted lure pages and a Cloudflare Workers redirect to deliver a Google Account phishing page. The final stage used custom CAPTCHA, anti-debugging logic, Web Crypto API decryption, and HTML redirection smuggling via the Blob API.
Researchers reported a credential phishing campaign using fake "New Audio MSG" emails that route victims through tracking and redirect infrastructure before landing on Google-themed credential-harvesting pages. The campaign carried a Base64-encoded copy of the recipient's email address through the redirect chain and used a Blob URL in the final phishing stage.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
levelblue.com
Open sourcecybersecuritynews.com
Open sourceresearch.splunk.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.